Entry passes that can’t be forged

Every confirmed player gets a signed QR pass tied to one event and one slot. It can’t be forged, it won’t scan anywhere else, and screenshots go stale.

The problem with a name on a list

A name on a spreadsheet is checked by a person reading a phone screen at a door, in a queue, in bad light. It cannot distinguish a registered player from someone who read the name off a Discord message, and it cannot tell you whether the person in front of you already came in an hour ago.

The same problem exists online: an organizer posting a lobby code to whoever says the right name ends up with people in the room who never registered — and, in a paid event, never paid.

What’s actually in the pass

A pass is a token signed on our server. It carries the participation it belongs to, the event it belongs to, and a rotating identifier. Signing means the contents cannot be altered without invalidating it: change the event, change the slot, change anything, and the signature stops matching.

Validation always happens server-side when a pass is scanned. The scanner is not deciding whether a pass is good — it is asking, and our server answers. That distinction is what makes a screenshot of the scanner’s green tick worthless.

Why it can’t be reused at another event

The event is inside the signed payload. A pass presented at a different tournament fails validation because the event it names is not the event doing the scanning — not because someone noticed, but because the check cannot pass.

What happens to a screenshotted pass

The pass carries a rotating identifier. When it rotates, previously issued copies stop validating, so a screenshot circulating in a group chat goes stale rather than remaining a permanent skeleton key.

What this does not stopA confirmed player who hands their live pass to someone else at the door can still get that person in, exactly as they could with a paper ticket. This prevents forgery and reuse, not collusion. If that matters at your event, check names at the door as well.

What a pass is not

  • Not a ticket. Fragnet sold you nothing and holds no money — the pass is proof the organizer approved your slot, not proof of purchase.
  • Not proof of payment. Whether an entry fee was paid is between you and the organizer.
  • Not identity verification. We do not know who you are; the pass says a confirmed participation exists, not that a particular person holds it.

Common questions

Do I need an app for my entry pass?
No. The pass lives on a page in your browser, and the organizer scans it with a page in theirs.
Someone screenshotted my pass — can they use it?
The pass carries a rotating identifier, so older copies stop validating once it rotates. Validation also happens on our server rather than in the scanner, so a faked screen cannot pass.
Can I use one pass at two events?
No. The event is part of the signed payload, so a pass will not validate anywhere except the event it was issued for.

Scan people in from a phone

The other half of this: a check-in scanner with no app to install.